TechNewsReel
Live

Trezor Breach Expands to 80,000 Customers After Shipping Partner Data Failure

A second wave of disclosures reveals that ShipMonk failed to delete years of customer records, contradicting earlier claims of a limited breach scope.

TechNewsReel Newsroom · September 4, 2026

Hardware wallet maker Trezor revealed on September 4, 2026, that a data breach at its shipping partner, ShipMonk, was significantly larger than first reported. The disclosure confirms that tens of thousands of additional users had their personal information exposed, undermining previous assurances regarding data retention.

According to Trezor and reports from Decrypt and Cyber Security News, approximately 67,000 additional U.S. customers were impacted in this second wave of disclosures. This brings the total number of affected users from an initial 13,689 to over 80,000. The exposed data includes names, email addresses, phone numbers, home addresses, and order numbers. The breach originated from a critical SQL injection vulnerability within Metabase, an analytics tool used by ShipMonk.

A Failure of Data Retention

Trezor first disclosed the ShipMonk breach in August 2026, initially claiming that a strict 90-day data retention policy had limited the scope of the leak. However, the latest findings show the breach affected records from a prior partnership spanning November 2019 to August 2021. It has since emerged that ShipMonk failed to delete these older records despite providing written confirmation to Trezor that the data had been purged.

This incident is not the first security lapse for the company's ecosystem. In January 2024, a breach of Trezor's third-party support portal exposed the information of 66,000 users, highlighting a recurring vulnerability in the company's reliance on external service providers.

Physical and Financial Risks

The exposure of home addresses linked to confirmed hardware wallet ownership creates a severe security risk for users. Because attackers now know exactly who owns a Trezor device and where they live, they can launch highly targeted "snail mail" phishing campaigns. By impersonating the company through physical letters, phone calls, or emails, attackers can attempt to trick users into revealing their 24-word recovery seeds. If a user discloses this seed, the attacker gains full and immediate access to the funds stored on the wallet.

What to Watch

Users are advised to remain vigilant against unsolicited communications and to remember that Trezor will never ask for a recovery seed. While the technical cause of the breach—the Metabase SQL injection—is identified, the focus now shifts to how Trezor will manage its third-party vendor audits to prevent similar retention failures. It remains to be seen if further audits of other partners will reveal additional exposed datasets.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.